
Cisco has disclosed stored cross-site scripting vulnerabilities in Identity Services Engine guest portals that could let an authenticated attacker with administrative credentials execute script in the management interface context. Updates are available, and Cisco says no workaround exists.



